<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cluster Interface for VLAN in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Cluster-Interface-for-VLAN/m-p/234493#M39155</link>
    <description>&lt;P&gt;All just wanted to update you all on this:&lt;/P&gt;&lt;P&gt;One more time&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;diagram&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;FW ----eth3-02.1925&amp;nbsp; =&amp;gt; Trunk port to layer 3 SW =&amp;gt; Trunk port to Metro-E =&amp;gt; Trunk Port 1ND VLAN1925&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;eth3-02.301&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So my original issue was when I went to the 1ND location and I just removed the ethernet cable from the switch, we started to get alerts on the firewall saying that the interface, eth3-02.1925 went down so I immediately plugged the cable back in.&amp;nbsp; So taking a look at this closer each interface is running OSPF on it so the VLAN1925 in 1ND is running OSPF on it as well.&amp;nbsp; So I went in during the Thanksgiving weekend and I unplugged it, received the same alerts but this time I waited for OSPF to converge, probably overkill I left the office to get a cup of coffee, took all about 15 mins and check firewall and no longer seeing any alerts,&amp;nbsp; They all cleared and firewall was happpy.&amp;nbsp; So now the topology looks like this&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;diagram&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;FW ----eth3-02.1925&amp;nbsp; =&amp;gt; Trunk port to layer 3 SW =&amp;gt; Trunk port to Metro-E&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;eth3-02.301&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have been monitoring this for a day or two and so far so go.&amp;nbsp; So I believe when I originally unplugged it and saw alerts panicked and plugged it back in, I didn't wait long enough for OSPF to converge.&amp;nbsp; &amp;nbsp;Thank you al for all your help and probably I wasn't clear on what I was trying to do but this seems to be the resolution.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you all!!!!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 03 Dec 2024 18:05:13 GMT</pubDate>
    <dc:creator>gurowar</dc:creator>
    <dc:date>2024-12-03T18:05:13Z</dc:date>
    <item>
      <title>Cluster Interface for VLAN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cluster-Interface-for-VLAN/m-p/233986#M39095</link>
      <description>&lt;P&gt;Good day all,&lt;/P&gt;&lt;P&gt;Hope everyone is ready for Thanksgiving!! I have a pair of 16200 FWs running&amp;nbsp;&lt;SPAN&gt;R81.10 Jumbo Hotfix Take 156 in a HA configuration.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have 2 sub-interfaces off of eth3-02:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;eth3-02.1925&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;eth3-02.301&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;both are connected to a trunk port to my layer 3 switch which in turn has a vlan1925 that connects to the Metro-E.&amp;nbsp; What I am trying to do is vlan1925 is connected to a metro-E to 2 other locations and we are in the process of decomming one site called 1ND. So I thought all I would need to do is at the 1ND location I can just disconnect the cable of the metro-E and be done with it.&amp;nbsp; But when I did that I received an alert on the firewall &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Alert: mail; OriginSicName: CN=FireWall01,O=CheckPointMgmt.omeda.local.oy6o8p; cluster_info: (ClusterXL) member 1 (192.168.255.253) is down (Interface Active Check on member 1 (192.168.255.253) detected a problem (eth3-02.1925 interface is down, 9 interfaces required, only 8 up).).; ProductName: VPN-1 &amp;amp; FireWall-1; ProductFamily: Network&lt;/P&gt;&lt;P&gt;&amp;nbsp;HeaderDateHour: 26Nov2024&amp;nbsp; 9:35:34; ContentVersion: 5; HighLevelLogKey: N/A; Uuid: {0x0,0x0,0x0,0x0}; SequenceNum: 98; Action: ctl; Origin: FireWall01; IfDir: &amp;gt;; IfName: N/A; Alert: mail; OriginSicName: CN=FireWall01,O=CheckPointMgmt.omeda.local.oy6o8p; cluster_info: (ClusterXL) member 2 (192.168.255.254) is down.; ProductName: VPN-1 &amp;amp; FireWall-1; ProductFamily: Network&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;HeaderDateHour: 26Nov2024&amp;nbsp; 9:35:34; ContentVersion: 5; HighLevelLogKey: N/A; Uuid: {0x0,0x0,0x0,0x0}; SequenceNum: 1; Action: ctl; Origin: FireWall02; IfDir: &amp;gt;; IfName: N/A; Alert: mail; OriginSicName: CN=FireWall02,O=CheckPointMgmt.omeda.local.oy6o8p; cluster_info: (ClusterXL) member 2 (192.168.255.254) is down (Interface Active Check on member 2 (192.168.255.254) detected a problem (eth3-02.1925 interface is down, 9 interfaces required, only 8 up).).; ProductName: VPN-1 &amp;amp; FireWall-1; ProductFamily: Network&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;why would it say that the interface 1925 is down on the firewall when I disconnected the cable from 1ND which is 40 miles west? When I plugged it back in everything cleared.&amp;nbsp; Should I have disabled and remove the VLAN/IP address first from the 1ND location instead of just unplugging it?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;diagram&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;FW ----eth3-02.1925&amp;nbsp; =&amp;gt; Trunk port to layer 3 SW =&amp;gt; Trunk port to Metro-E =&amp;gt; Trunk Port 1ND VLAN1925&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;eth3-02.301&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you in advance!!!!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2024 18:03:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cluster-Interface-for-VLAN/m-p/233986#M39095</guid>
      <dc:creator>gurowar</dc:creator>
      <dc:date>2024-11-27T18:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Interface for VLAN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cluster-Interface-for-VLAN/m-p/233993#M39096</link>
      <description>&lt;P&gt;ClusterXL monitors the state of all interfaces on cluster members.&lt;BR /&gt;If one of the members loses access to one of their monitored interfaces...you'll get that message.&lt;BR /&gt;See also:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk61323" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk61323&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2024 18:50:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cluster-Interface-for-VLAN/m-p/233993#M39096</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-11-27T18:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Interface for VLAN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cluster-Interface-for-VLAN/m-p/233994#M39097</link>
      <description>&lt;P&gt;So according to the SK61323 my set up is that it is monitoring both the high and low vlans.&amp;nbsp; I only have 2 vlans:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;vlan302&lt;/P&gt;&lt;P&gt;vlan1925&lt;/P&gt;&lt;P&gt;[Expert@Firewall01:0]# fw ctl get int fwha_monitor_low_high_vlans&lt;BR /&gt;fwha_monitor_low_high_vlans = 1&lt;/P&gt;&lt;P&gt;so if I change it to 0 then only the lowest vlan will be monitored, in my case only vlan302.&amp;nbsp; So then I should be able to go to 1ND and unplug the cable and we should be good to go or am I reading this incorrectly?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2024 19:06:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cluster-Interface-for-VLAN/m-p/233994#M39097</guid>
      <dc:creator>gurowar</dc:creator>
      <dc:date>2024-11-27T19:06:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Interface for VLAN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cluster-Interface-for-VLAN/m-p/233998#M39099</link>
      <description>&lt;P&gt;I believe if its set to 1, ONLY lowest and highest vlans are monitored. If its 0, then most likely just lowest. To answer your question, yes, thats my understanding as well, you should be good.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2024 23:49:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cluster-Interface-for-VLAN/m-p/233998#M39099</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-27T23:49:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Interface for VLAN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cluster-Interface-for-VLAN/m-p/234006#M39103</link>
      <description>&lt;P&gt;If the VLAN and switching layer is operating properly then the two cluster members should always see each other on the VLAN and that will satisfy the monitoring requirements. If the VLAN itself is disappearing from the trunk then yes, either change the monitoring or remove the interface (or set it to private/non-monitored in the topology section in the cluster object in smartconsole)&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2024 02:19:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cluster-Interface-for-VLAN/m-p/234006#M39103</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-11-28T02:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Interface for VLAN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cluster-Interface-for-VLAN/m-p/234493#M39155</link>
      <description>&lt;P&gt;All just wanted to update you all on this:&lt;/P&gt;&lt;P&gt;One more time&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;diagram&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;FW ----eth3-02.1925&amp;nbsp; =&amp;gt; Trunk port to layer 3 SW =&amp;gt; Trunk port to Metro-E =&amp;gt; Trunk Port 1ND VLAN1925&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;eth3-02.301&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So my original issue was when I went to the 1ND location and I just removed the ethernet cable from the switch, we started to get alerts on the firewall saying that the interface, eth3-02.1925 went down so I immediately plugged the cable back in.&amp;nbsp; So taking a look at this closer each interface is running OSPF on it so the VLAN1925 in 1ND is running OSPF on it as well.&amp;nbsp; So I went in during the Thanksgiving weekend and I unplugged it, received the same alerts but this time I waited for OSPF to converge, probably overkill I left the office to get a cup of coffee, took all about 15 mins and check firewall and no longer seeing any alerts,&amp;nbsp; They all cleared and firewall was happpy.&amp;nbsp; So now the topology looks like this&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;diagram&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;FW ----eth3-02.1925&amp;nbsp; =&amp;gt; Trunk port to layer 3 SW =&amp;gt; Trunk port to Metro-E&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;eth3-02.301&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have been monitoring this for a day or two and so far so go.&amp;nbsp; So I believe when I originally unplugged it and saw alerts panicked and plugged it back in, I didn't wait long enough for OSPF to converge.&amp;nbsp; &amp;nbsp;Thank you al for all your help and probably I wasn't clear on what I was trying to do but this seems to be the resolution.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you all!!!!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2024 18:05:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cluster-Interface-for-VLAN/m-p/234493#M39155</guid>
      <dc:creator>gurowar</dc:creator>
      <dc:date>2024-12-03T18:05:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Interface for VLAN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cluster-Interface-for-VLAN/m-p/234509#M39160</link>
      <description>&lt;P&gt;Are member 1 and member 2 on the &lt;STRONG&gt;same&lt;/STRONG&gt; VLAN 1925? That is, are they able to talk to each other over that network?&lt;/P&gt;
&lt;P&gt;Is VLAN 1925 the highest VLAN ID on the interface? You mentioned you have two subinterfaces, but you didn't say you have&amp;nbsp;&lt;STRONG&gt;only&lt;/STRONG&gt; two subinterfaces.&lt;/P&gt;
&lt;P&gt;Are there any other devices with IP addresses on VLAN 1925?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2024 21:47:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cluster-Interface-for-VLAN/m-p/234509#M39160</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2024-12-03T21:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Interface for VLAN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cluster-Interface-for-VLAN/m-p/234657#M39204</link>
      <description>&lt;P&gt;HI Bob,&lt;/P&gt;&lt;P&gt;Yes member 1 and 2 are the same VLAN1925, they are set up in a HA configuration&amp;nbsp;&lt;/P&gt;&lt;P&gt;member 1 - &lt;SPAN&gt;eth3-02.1925&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;192.168.5.2&amp;nbsp; &amp;nbsp;------Trunk----------- SW1 gi0/2 ---gi0/10 Trunk Metro-E ------------------ Chicago&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;Firewall&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;HA - 192.168.5.1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Stack SW&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;NYC&lt;/P&gt;&lt;P&gt;member 2 - &lt;SPAN&gt;eth3-02.1925&amp;nbsp;&lt;/SPAN&gt;192.168.5.3&amp;nbsp; ------Trunk------------SW1&amp;nbsp; gi12&lt;/P&gt;&lt;P&gt;I hope that makes sense; this is a metro-E that connect 3 sites&amp;nbsp;&lt;/P&gt;&lt;P&gt;DataCeter&lt;/P&gt;&lt;P&gt;Chicago&amp;nbsp;&lt;/P&gt;&lt;P&gt;NYC&lt;/P&gt;&lt;P&gt;The firewall sits in the DC, each firewall has a physical connection the Switch Stack, from the same SW stack there is an interface that is a trunk port that connects to the Metro-E and via the Metro-E&amp;nbsp; Chi and NYC are connected.&amp;nbsp; So what happened is the other day I was in the Chi office and since we are decomming this site got lazy and figure I would just remove the cable from the switch that connects Chi office to the Metro-E.&amp;nbsp; When I did that I received alarms that I was expecting but the one the caught my attention was the alert on received from the Firewall saying that interface&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 21:05:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cluster-Interface-for-VLAN/m-p/234657#M39204</guid>
      <dc:creator>gurowar</dc:creator>
      <dc:date>2024-12-04T21:05:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Interface for VLAN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cluster-Interface-for-VLAN/m-p/234659#M39205</link>
      <description>&lt;P&gt;ROUTED is a monitored PNOTE for ClusterXL. &amp;nbsp;When OSPF lost its DR (likely the peer on the other end of the link), OSPF registered the fault to ROUTED thus to ClusterXL. &amp;nbsp;You must not have had a BDR for some reason (ospf link-type point-to-point?). &amp;nbsp;When OSPF had a new DR, the PNOTE cleared with ROUTED.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 21:43:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cluster-Interface-for-VLAN/m-p/234659#M39205</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2024-12-04T21:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Interface for VLAN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cluster-Interface-for-VLAN/m-p/234660#M39206</link>
      <description>&lt;P&gt;Hi Duane,&lt;/P&gt;&lt;P&gt;Between the sites there was a DR and BDR but you know come to think of it I did notice something weird about the BDR and told myself I would look into it later but later never came cause we ended up decomming the site.&amp;nbsp; But I agree with you about OSPF and gave it as much time to reconverge.&amp;nbsp; So I believe your right about that.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 21:52:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cluster-Interface-for-VLAN/m-p/234660#M39206</guid>
      <dc:creator>gurowar</dc:creator>
      <dc:date>2024-12-04T21:52:55Z</dc:date>
    </item>
  </channel>
</rss>

